using System;
using System.Data;
using System.Configuration;
using System.Collections;
using System.Web;
using System.Web.Security;
using System.Web.UI;
using System.Web.UI.WebControls;
using System.Web.UI.WebControls.WebParts;
using System.Web.UI.HtmlControls;
using System.Data.SqlClient;

public partial class admin_EMP_create_user : System.Web.UI.Page
{
    func fn = new func();
    SqlConnection conn;
    protected void Page_Load(object sender, EventArgs e)
    {
        conn = fn.getConnection();
    }
    protected void btnCreate_Click(object sender, EventArgs e)
    {
        //kiem tra ton tai users
        if (fn.checkExistUserByNumberID(txtNumberID.Text) == true) {
            lblThongbao.Text = "Existing Number ID";
        }
        Random random = new Random();
        string fname = txtFname.Text.Replace(" ", "");
        int length = 0;
        if (fname.Length-5 > 6) {
            length = fname.Length - 5;
        }
        fname = fname.Substring(0, fname.Length - length) + random.Next(0, 99999).ToString();
        while (fn.checkExistUserByUserName(fname))
        {
            fname = fname.Substring(0, fname.Length - length) + random.Next(0, 99999).ToString();
        }

        string username = fname;
        //create customer
        
        string sql = @" insert into users('BranchID','UserName','Password','Level','NumberID','FirstName','LastName','Phone','Address','CreateDate','Status',)
        values('" + Session["branchid"].ToString() + "','" + username + "','" + username + "','3','" + txtFname.Text + "','" + txtLname.Text + "','" + txtPhone.Text + "','" + txtAddress.Text + "','"+DateTime.Now.ToString("yyyy-M-d h:mm:s")+"',1)";
        lblThongbao.Text = sql;

        //if (fn.EXECQUERY(sql) != 0) {
        //    lblThongbao.Text = "Cannot create customer";
        //}//end create customer
        
        //load info
        lblUsername.Text = username;
        lblFname.Text = txtFname.Text;
        lblLname.Text = txtLname.Text;
        lblPhone.Text = txtPhone.Text;
        lblAddress.Text = txtAddress.Text;

        sql = "select * from Branches where BranchID='"+Session["branchid"].ToString()+"'";
        DataRow dr = fn.GETDATAROWS(sql);
        lblBranch.Text = dr["BranchName"].ToString();

        //pnInfoCustomer.Visible = true;
        //pnCreateCustomer.Visible = false;



    }
    protected void btnNext_Click(object sender, EventArgs e)
    {
        DataRow dr = fn.getUsersInfoByUsername(lblUsername.Text);
        Response.Redirect("waybills.aspx?cid="+dr["UserID"].ToString());

    }
}
